Skip to main content

PROFESSIONAL-CLOUD-ARCHITECT Real Exam Questions

Professional Cloud Architect on Google Cloud Platform

317 questions available · Page 1 of 32

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Case Study 9

Company overview

EHR Healthcare is a leading provider of electronic health record software to the medical industry. EHR Healthcare provides their software as a service to multi-national medical offices, hospitals, and insurance providers.

Solution concept

Due to rapid changes in the healthcare and insurance industry, EHR Healthcare's business has been growing exponentially year over year. They need to be able to scale their environment, adapt their disaster recovery plan, and roll out new continuous deployment capabilities to update their software at a fast pace.
Google Cloud has been chosen to replace their current colocation facilities.

Existing technical environment

EHR's software is currently hosted in multiple colocation facilities. The lease on one of the data centers is about to expire.

Customer-facing applications are web-based, and many have recently been containerized to run on a group of Kubernetes clusters. Data is stored in a mixture of relational and NoSQL databases (MySQL, MS SQL Server, Redis, and MongoDB).

EHR is hosting several legacy file-and API-based integrations with insurance providers on-premises.
These systems are scheduled to be replaced over the next several years. There is no plan to upgrade or move these systems at the current time.

Users are managed via Microsoft Active Directory. Monitoring is currently being done via various open source tools. Alerts are sent via email and are often ignored.

Business requirements

1. On-board new insurance providers as quickly as possible.
2. Provide a minimum 99.9% availability for all customer-facing systems.
3. Provide centralized visibility and proactive action on system performance and usage.
4. Increase ability to provide insights into healthcare trends.
5. Reduce latency to all customers.
6. Maintain regulatory compliance.
7. Decrease infrastructure administration costs.
8. Make predictions and generate reports on industry trends based on provider data.

Technical requirements

1. Maintain legacy interfaces to insurance providers with connectivity to both on-premises systems and cloud providers.
2. Provide a consistent way to manage customer-facing applications that are container-based.
3. Provide a secure and high-performance connection between on-premises systems and Google Cloud.
4. Provide consistent logging, log retention, monitoring, and alerting capabilities.
5. Maintain and manage multiple container-based environments.
6. Dynamically scale and provision new environments.
7. Create interfaces to ingest and process data from new providers.

Executive statement

Our on-premises strategy has worked for years but has required a major investment of time and money in training our team on distinctly different systems, managing similar but separate environments, and responding to outages. Many of these outages have been a result of misconfigured systems, inadequate capacity to manage spikes in traffic, and inconsistent monitoring practices. We want to use Google Cloud to leverage a scalable, resilient platform that can span multiple environments seamlessly and provide a

consistent and stable user experience that positions us for future growth.

Question 1 Single choice

For this question, refer to the EHR Healthcare case study. You need to define the technical architecture for hybrid connectivity between EHR's on-premises systems and Google Cloud. You want to follow Google's recommended practices for production-level applications.

Considering the EHR Healthcare business and technical requirements, what should you do?

  1. A

    Configure two Partner Interconnect connections in one metro (City), and make sure the Interconnect connections are placed in different metro zones.

  2. B

    Configure two VPN connections from on-premises to Google Cloud, and make sure the VPN devices on-premises are in separate racks.

  3. C

    Configure Direct Peering between EHR Healthcare and Google Cloud, and make sure you are peering at least two Google locations.

  4. D

    Configure two Dedicated Interconnect connections in one metro (City) and two connections in another metro, and make sure the Interconnect connections are placed in different metro zones.

Show answer and explanation

Correct answer: D

Explanation

based on the requirement of secure and high-performance connection between on-premises systems to Google Cloud
https://cloud.google.com/network-connectivity/docs/interconnect/tutorials/partner-creating-9999-availability

Question 2 Single choice

Your company has an application running as a Deployment in a Google Kubernetes Engine (GKE) cluster.
When releasing new versions of the application via a rolling deployment, the team has been causing outages. The root cause of the outages is misconfigurations with parameters that are only used in production. You want to put preventive measures for this in the platform to prevent outages.

What should you do?

  1. A

    Configure liveness and readiness probes in the Pod specification.

  2. B

    Configure an uptime alert in Cloud Monitoring.

  3. C

    Create a Scheduled Task to check whether the application is available.

  4. D

    Configure health checks on the managed instance group.

Show answer and explanation

Correct answer: A

Explanation

https://cloud.google.com/blog/products/containers-kubernetes/kubernetes-best-practices-setting-up-health-checks-with-readiness-and-liveness-probes

Question 3 Single choice

You are configuring the cloud network architecture for a newly created project in Google Cloud that will host applications in Compute Engine. Compute Engine virtual machine instances will be created in two different subnets (sub-a and sub-b) within a single region:

1. Instances in sub-a will have public IP addresses.
2. Instances in sub-b will have only private IP addresses.

To download updated packages, instances must connect to a public repository outside the boundaries of Google Cloud. You need to allow sub-b to access the external repository.

What should you do?

  1. A

    Enable Private Google Access on sub-b.

  2. B

    Configure Cloud NAT and select sub-b in the NAT mapping section.

  3. C

    Configure a bastion host instance in sub-a to connect to instances in sub-b.

  4. D

    Enable Identity-Aware Proxy for TCP forwarding for instances in sub-b.

Show answer and explanation

Correct answer: B

Explanation

Cloud NAT (network address translation) lets Google Cloud virtual machine (VM) instances without external IP addresses and private Google Kubernetes Engine (GKE) clusters send outbound packets to the internet and receive any corresponding established inbound response packets. By configuring Cloud NAT and selecting sub-b in the NAT mapping section, you can allow instances in sub-b to access the external repository without exposing them to the internet.

Question 4 Single choice

Your company has an application deployed on Anthos clusters (formerly Anthos GKE) that is running multiple microservices. The cluster has both Anthos Service Mesh and Anthos Config Management configured. End users inform you that the application is responding very slowly. You want to identify the microservice that is causing the delay.

What should you do?

  1. A

    Use the Service Mesh visualization in the Cloud Console to inspect the telemetry between the microservices.

  2. B

    Use Anthos Config Management to create a ClusterSelector selecting the relevant cluster. On the Google Cloud Console page for Google Kubernetes Engine, view the Workloads and filter on the cluster. Inspect the configurations of the filtered workloads.

  3. C

    Use Anthos Config Management to create a namespaceSelector selecting the relevant cluster namespace. On the Google Cloud Console page for Google Kubernetes Engine, visit the workloads and filter on the namespace. Inspect the configurations of the filtered workloads.

  4. D

    Reinstall istio using the default istio profile in order to collect request latency. Evaluate the telemetry between the microservices in the Cloud Console.

Show answer and explanation

Correct answer: A

Explanation

The Anthos Service Mesh pages in the Google Cloud Console provide both summary and in-depth metrics, charts, and graphs that enable you to observe service behavior. You can monitor the overall health of your services, or drill down on a specific service to set a service level objective (SLO) or troubleshoot an issue.
https://cloud.google.com/service-mesh/docs/observability/explore-dashboard
https://cloud.google.com/anthos/service-mesh

Case Study 4

Company Overview

TerramEarth manufactures heavy equipment for the mining and agricultural industries: about 80% of their business is from mining and 20% from agriculture. They currently have over 500 dealers and service centers in 100 countries. Their mission is to build products that make their customers more productive.

Company background

TerramEarth was formed in 1946, when several small, family owned companies combined to retool after World War II. The company cares about their employees and customers and considers them to be extended members of their family.

TerramEarth is proud of their ability to innovate on their core products and find new markets as their customers' needs change. For the past 20 years, trends in the industry have been largely toward increasing productivity by using larger vehicles with a human operator.

Solution Concept

There are 20 million TerramEarth vehicles in operation that collect 120 fields of data per second. Data is stored locally on the vehicle and can be accessed for analysis when a vehicle is serviced. The data is downloaded via a maintenance port. This same port can be used to adjust operational parameters, allowing the vehicles to be upgraded in the field with new computing modules.

Approximately 200,000 vehicles are connected to a cellular network, allowing TerramEarth to collect data directly. At a rate of 120 fields of data per second with 22 hours of operation per day, Terram Earth collects a total of about 9 TB/day from these connected vehicles.

Existing Technical Environment

TerramEarth's existing architecture is composed of Linux-based systems that reside in a data center.
These systems gzip CSV files from the field and upload via FTP, transform and aggregate them, and place the data in their data warehouse. Because this process takes time, aggregated reports are based on data that is 3 weeks old.

With this data, TerramEarth has been able to preemptively stock replacement parts and reduce unplanned downtime of their vehicles by 60%. However, because the data is stale, some customers are without their vehicles for up to 4 weeks while they wait for replacement parts.

Business Requirements

1. Decrease unplanned vehicle downtime to less than 1 week, without increasing the cost of carrying

surplus inventory
2. Support the dealer network with more data on how their customers use their equipment to better position new products and services
3. Have the ability to partner with different companies - especially with seed and fertilizer suppliers in the fast-growing agricultural business - to create compelling joint offerings for their customers.

CEO Statement

We have been successful in capitalizing on the trend toward larger vehicles to increase the productivity of our customers. Technological change is occurring rapidly, and TerramEarth has taken advantage of connected devices technology to provide our customers with better services, such as our intelligent farming equipment. With this technology, we have been able to increase farmers' yields by 25%, by using past trends to adjust how our vehicles operate. These advances have led to the rapid growth of our agricultural product line, which we expect will generate 50% of our revenues by 2020.

CTO Statement

Our competitive advantage has always been in the manufacturing process, with our ability to build better vehicles for lower cost than our competitors. However, new products with different approaches are constantly being developed, and I'm concerned that we lack the skills to undergo the next wave of transformations in our industry. Unfortunately, our CEO doesn't take technology obsolescence seriously and he considers the many new companies in our industry to be niche players. My goals are to build our skills while addressing immediate market needs through incremental innovations.

Question 5 Single choice

TerramEarth plans to connect all 20 million vehicles in the field to the cloud. This increases the volume to 20 million 600 byte records a second for 40 TB an hour.

How should you design the data ingestion?

  1. A

    Vehicles write data directly to GCS

  2. B

    Vehicles write data directly to Google Cloud Pub/Sub

  3. C

    Vehicles stream data directly to Google BigQuery

  4. D

    Vehicles continue to write data using the existing system (FTP)

Show answer and explanation

Correct answer: B

Explanation

Streamed data is available for real-time analysis within a few seconds of the first streaming insertion into a table.

Instead of using a job to load data into BigQuery, you can choose to stream your data into BigQuery one record at a time by using the tabledata().insertAll() method. This approach enables querying data without the delay of running a load job.

References:
https://cloud.google.com/bigquery/streaming-data-into-bigquery

Question 6 Single choice

You are deploying a critical application with a stateless, containerized frontend on Cloud Run and a Cloud SQL for PostgreSQL backend. The application experiences unpredictable traffic spikes, and the business requires the ability to immediately roll back a failed deployment to the last known good state. You need to apply a deployment strategy that aligns with Site Reliability Engineering (SRE) principles for both the application code and the database schema updates, while meeting the business's requirements.

What should you do?

  1. A

    Package the database schema migration script within the container to be executed on every container startup before the application process begins.

  2. B

    Configure the CI/CD pipeline to use the :latest container tag for deployments, with database schema changes applied manually as needed.

  3. C

    Separate CI/CD pipelines for database schema migrations from application deployments. When deploying a new Cloud Run revision, use gradual traffic split.

  4. D

    Use a single CI/CD pipeline that first applies database schema changes and then deploys the new Cloud Run revision.

Show answer and explanation

Correct answer: C

Explanation

Following SRE and DevOps best practices, database schema migrations should be managed separately from application deployments to ensure safe rollbacks and reduce coupling. Using gradual traffic splitting for Cloud Run allows canary-style rollouts - gradually shifting traffic to the new revision and instantly reverting to the previous one if issues arise. This approach minimizes risk during spikes, enables rapid rollback, and keeps schema changes controlled and auditable in their own pipeline.

Question 7 Single choice

You are responsible for the Google Cloud environment in your company. Multiple departments need access to their own projects, and the members within each department will have the same project responsibilities.

You want to structure your Google Cloud environment for minimal maintenance and maximum overview of IAM permissions as each department's projects start and end.

You want to follow Google-recommended practices.

What should you do?

  1. A

    Create a Google Group per department and add all department members to their respective groups.
    Create a folder per department and grant the respective group the required IAM permissions at the folder level. Add the projects under the respective folders.

  2. B

    Grant all department members the required IAM permissions for their respective projects.

  3. C

    Create a Google Group per department and add all department members to their respective groups.
    Grant each group the required IAM permissions for their respective projects.

  4. D

    Create a folder per department and grant the respective members of the department the required IAM permissions at the folder level. Structure all projects for each department under the respective folders.

Show answer and explanation

Correct answer: A

Explanation

This option follows the Google-recommended practices for structuring a Google Cloud environment for minimal maintenance and maximum overview of IAM permissions. By creating a Google Group per department and adding all department members to their respective groups, you can simplify user management and avoid granting IAM permissions to individual users. By creating a folder per department and granting the respective group the required IAM permissions at the folder level, you can enforce consistent policies across all projects within each department and avoid granting IAM permissions at the project level. By adding the projects under the respective folders, you can organize your resources hierarchically and leverage inheritance of IAM policies from folders to projects. The other options are not optimal for this scenario, because they either require granting IAM permissions to individual users (B, C), or do not use Google Groups to manage users (D).
References:
https://cloud.google.com/architecture/framework/system-design
https://cloud.google.com/architecture/identity/best-practices-for-planning
https://cloud.google.com/resource-manager/docs/creating-managing-folders

Question 8 Single choice

Your architecture calls for the centralized collection of all admin activity and VM system logs within your project.

How should you collect these logs from both VMs and services?

  1. A

    All admin and VM system logs are automatically collected by Stackdriver.

  2. B

    Stackdriver automatically collects admin activity logs for most services. The Stackdriver Logging agent must be installed on each instance to collect system logs.

  3. C

    Launch a custom syslogd compute instance and configure your GCP project and VMs to forward all logs to it.

  4. D

    Install the Stackdriver Logging agent on a single compute instance and let it collect all audit and access logs for your environment.

Show answer and explanation

Correct answer: B

Explanation

https://cloud.google.com/logging/docs/agent/default-logs

Question 9 Single choice

You need to deploy a stateful workload on Google Cloud. The workload can scale horizontally, but each instance needs to read and write to the same POSIX filesystem. At high load, the stateful workload needs to support up to 100 MB/s of writes.

What should you do?

  1. A

    Use a persistent disk for each instance.

  2. B

    Use a regional persistent disk for each instance.

  3. C

    Create a Cloud Filestore instance and mount it in each instance.

  4. D

    Create a Cloud Storage bucket and mount it in each instance using gcsfuse.

Show answer and explanation

Correct answer: C

Explanation

https://cloud.google.com/storage/docs/gcs-fuse#notes
Cloud Filestore: Cloud Filestore is a scalable and highly available shared file service fully managed by Google. Cloud Filestore provides persistent storage ideal for shared workloads. It is best suited for enterprise applications requiring persistent, durable, shared storage which is accessed by NFS or requires a POSIX compliant file system.

References:
https://cloud.google.com/storage/docs/gcs-fuse

Question 10 Single choice

You are designing a globally distributed OLTP system that requires relational schemas, strong consistency, and horizontal scaling across regions with high availability.

Which database should you use?

  1. A

    Cloud SQL

  2. B

    BigQuery

  3. C

    Cloud Spanner

  4. D

    Cloud Storage

Show answer and explanation

Correct answer: C

Explanation

Cloud Spanner is designed for globally distributed, strongly consistent relational workloads with horizontal scalability and high availability. Cloud SQL (A) is regional and typically scales vertically with read replicas.
BigQuery (B) is an analytic data warehouse. Cloud Storage (D) is object storage and not a relational database.